CVE-2026-41069Medium· 6.5▾ Sunlitlibheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.
libheif < 1.22.0Upgrade past the affected range:
libheif 1.22.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41071High· 8.1libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84451Medium· 6.5libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84448Medium· 4.0libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84449Low· 3.7libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84450Medium· 4.3libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84444High· 7.4libheif is a HEIF and AVIF file format decoder and encoder